CIS Bottlerocket L1

Audit Details

Name: CIS Bottlerocket L1

Updated: 2/23/2024

Authority: CIS

Plugin: Unix

Revision: 1.0

Estimated Item Count: 14

File Details

Filename: CIS_Bottlerocket_v1.0.0_L1.audit

Size: 32.2 kB

MD5: ad7cf25d5fb4ee40dfe790074136494b
SHA256: b194cb89ce08443bdd7164baea16946bf627158296c4b4ddfa8b87902d905ab8

Audit Items

DescriptionCategories
1.2.1 Ensure software update repositories are configured

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

1.3.1 Ensure dm-verity is configured

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.4.1 Ensure setuid programs do not create core dumps

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.4.2 Ensure address space layout randomization (ASLR) is enabled

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.4.3 Ensure unprivileged eBPF is disabled

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

1.5.1 Ensure SELinux is configured

ACCESS CONTROL, MEDIA PROTECTION

1.6 Ensure updates, patches, and additional security software are installed

RISK ASSESSMENT, SYSTEM AND INFORMATION INTEGRITY

2.1.1.1 Ensure chrony is configured

AUDIT AND ACCOUNTABILITY

3.2.5 Ensure broadcast ICMP requests are ignored

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.6 Ensure bogus ICMP responses are ignored

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

3.2.7 Ensure TCP SYN Cookies is enabled

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

4.1.1.1 Ensure journald is configured to write logfiles to persistent disk

AUDIT AND ACCOUNTABILITY

4.1.2 Ensure permissions on journal files are configured

CONFIGURATION MANAGEMENT, SYSTEM AND SERVICES ACQUISITION

CIS_Bottlerocket_v1.0.0_L1.audit from CIS Bottlerocket Benchmark Level 1